
On-chain traces show proceeds from the two 2026 exploits converging in shared Bitcoin wallets, reinforcing suspicion of a Lazarus Group-linked laundering pipeline and complicating recovery efforts.
Stolen funds from the Humanity Protocol and Kelp DAO attacks have converged in shared wallets after the Humanity attacker moved 15,403 ETH, worth about $23.6 million, to a new Ethereum address and then bridged the funds onto Bitcoin, where they mixed with proceeds tied to the April Kelp DAO exploit. ZachXBT and blockchain analyst Specter said the flow is consistent with a single laundering pipeline often associated with the Lazarus Group. The Kelp DAO attack on April 18 was previously tied by Chainalysis to a compromise of internal RPC nodes operated by LayerZero Labs alongside a DDoS attack on external nodes, allowing 116,500 rsETH to be released without a corresponding burn on the source chain. Arbitrum’s Security Council froze more than 30,000 ETH of downstream funds, while KelpDAO’s emergency pause blocked another $95 million from being drained. Humanity Protocol’s June breach followed a different intrusion path but was also linked to North Korea-linked actors in post-mortem findings. Quantstamp said a company director, Chong Yee Wai, was phished through an email impersonating Bithumb, giving the attacker remote access to a Windows machine and access to MetaMask keys. The attacker then minted and sold unauthorized $H tokens on Ethereum and BNB Smart Chain, sending the token down roughly 89%. Quantstamp said known attacker addresses held more than $21 million in ETH. The overlap in stolen-fund flows adds to evidence that the two incidents may be connected and may also intensify legal disputes over frozen assets. Plaintiffs seeking to enforce more than $877 million in unpaid U.S. judgments against North Korea have already targeted about 30,766 ETH frozen after the Kelp DAO exploit, while Arbitrum governance had been pursuing a separate recovery plan backed by Aave Labs, KelpDAO, LayerZero, EtherFi and Compound.